Some outcomes can be annoying, but the net result is still positive, for the consumers and their data privacy at least.
Some outcomes can be annoying, but the net result is still positive, for the consumers and their data privacy at least.
https://arxiv.org/abs/2411.06862
https://netzpolitik.org/2025/databroker-files-targeting-the-...
Another issue is that controllers generally do not need to change their behavior before the final lawful decision which can take a lot of time to go through the court system, especially if it needs CJEU referral. And once the decision comes in force they can often make small changes and restart the whole process.
Also another issue is that DPAs do not often initiate the investigations themselves (unless breach is involved), they only happen at the request of data subjects and not that many people bother making complaints or follow them up. Just yesterday I had to follow up with 9 page reply to the controller's response to the DPA inquiry.
Additionally ePD and GDPR enforcement is sometimes split between different agencies. In those cases GDPR agency tends to wait for ePD case to be solved before investigating the GDPR aspects, often because the ePD consent validity will affects e.g. GDPR legal basis analysis.
It’s an ongoing fight for sure but it’s some fight at least.
I'd classify mandatory encryption backdoors as an industry crisis rather than an annoyance.
[though you are not wrong that encryption backdoors are a backwards step on individuals rights to privacy]
And while, sure, adtech corpos maybe won't due to the bad PR, what about the Kremlin, criminal organizations, or your insane abusive ex?
> You can't make backdoors only the "good guys" can access.
incomprehensible. I’m sure genuinely so, even.
Encryption backdoors is not a case of extending reach for a government, but an effort to get the capabilities back.
They were able to do that before. They just want to be able to continue now.
Note: No, I don't support the idea of backdoors. On the contrary.
The reason is that they have been trying again and again to do this in various forms, slightly modifying tactics so any opposition to it has to start from scratch.
2015 - https://techcrunch.com/2015/10/29/encryption-rhetoric-untang...
2016 - https://techcrunch.com/2016/08/24/encryption-under-fire-in-e...
2017 - https://www.theguardian.com/technology/2017/jun/19/eu-outlaw...
2020 - https://www.consilium.europa.eu/en/press/press-releases/2020...
2021 - https://www.consilium.europa.eu/en/press/press-releases/2021...
2023 - https://www.wired.com/story/europe-break-encryption-leaked-d...
2025 - https://www.techspot.com/news/107408-europe-proposes-backdoo...
2026 - https://www.euronews.com/next/2026/07/10/chat-control-10-pas...
If you wanted to make the corresponsing strong argument for Chat Control and its ilk, the EU just wants (the juicy part of) what the US already has. The remote root level control of most end user devices is not under EU juristiction. So they naturally want companies operating in the EU to give them one piece of access to the presentation layer, too.
This argument is what one must be prepared for, the encryption itself is less relevant..
Chat control is merely their newest attempt at this, carefully navigating around the reasons it was opposed last year.
They keep trying to legislate encryption backdoors by any means, and once they manage to get their foot into the door every other country will use that as a precedent to also mandate it.
As long as you manage to navigate all the dark patterns and not accidentally give your "informed consent".
Just set up your user agent to work as you wish, isn't that simpler than have unelected, technologic dumb bureaucrats writing laws that are complex and don't solve the issue?
Which has nothing to do with the stalking of the adtech industry, unless you are suggesting that the EU might sell access to the keys to the likes of OpenAI [though you are not wrong that encryption backdoors are a backwards step on individuals rights to privacy]
Things could be worse. It could be like most of the US where there are both no (or at least far fewer) protections against invasive behaviour of private companies and the government actively trying to backdoor private comms.
It has a lot to do with the practices of the adtech industry. If privacy is protected and upheld vis-a-vis the government (or meta-government in case of the EU), it may be upheld vis-a-vis private corporations and other governments. But if the government likes to be able to spy on its citizens, it will not foster mechanisms, practices and a culture of private communications.
But - I agree that it could be much worse.
> Things could be worse. It could be like most of the US
Yep, it could definitely be worse, but your response ignored the obvious intention behind my question. Saying, "but the US is bad, too" doesn't make your prior take of EU law being a net good for privacy any less uninformed.
Privacy has been dead for some time now. The fact is most business people never figure out how they are exploited. The modern intelligence campaigns just made it economical to hit almost everyone regardless of scale... often under some silly pretense like terrorists wanting our underpants. =3
All the EU bureaucrats can do is regulate, that's why it's so difficult to do business in the EU and that's why there is so little innovation over here. If Microsoft and Apple were started in the EU they would've been shut down within a week because you can't operate from a garage.
I guess that every once in a while this might have a positive outcome for consumers, a broken clock is right twice a day.
And, regarding the original topic, we wouldn't have many of these privacy issues if the US had not strategically failed to regulate its obnoxious tech monopolies
The innovation gap is real but it’s not just to do with regulation. It’s a lot to do with concentrated capital networks (eg Silicon Valley). And sure, the tech giants are in the USA but it’s not like there’s no innovation in the EU. Spotify in Sweden. Challenger banks in the U.K. (included as Monzo predates Brexit). And plenty of innovation - they just get bought by US companies. Which is a financial market weakness, not a regulatory one.
https://www.computerworld.com/article/4087347/european-commi...